PCI DSS v4.0
Security

Password & Authentication Policy Template

Password complexity, authentication requirements, and account management for all CDE system components.

What This Policy Covers

Purpose and Scope-Policy objectives and all system component accounts.
Password Requirements-Minimum 12 characters, complexity, history, and rotation.
Multi-Factor Authentication-MFA requirements for all CDE and remote access.
Account Lockout and Timeout-Failed attempt lockout and session inactivity timeout.
Unique User IDs-Prohibition on shared credentials and group accounts.
Service and System Account Management-Non-interactive account controls and password rotation.
Vendor Default Credentials-Mandatory change of all vendor-supplied defaults.

Required Sections

A compliant Password & Authentication Policy for PCI DSS v4.0 must include the following7 sections. Each section addresses a specific control requirement that auditors will review.

1

Purpose and Scope

Policy objectives and all system component accounts.

2

Password Requirements

Minimum 12 characters, complexity, history, and rotation.

3

Multi-Factor Authentication

MFA requirements for all CDE and remote access.

4

Account Lockout and Timeout

Failed attempt lockout and session inactivity timeout.

5

Unique User IDs

Prohibition on shared credentials and group accounts.

6

Service and System Account Management

Non-interactive account controls and password rotation.

7

Vendor Default Credentials

Mandatory change of all vendor-supplied defaults.

Generate a Customized Version

This template shows the required structure. PoliWriter generates a fully customized Password & Authentication Policy that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.